NiKoTiN1337 | 07.06.2015 13:07 | Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 07.06.2015
Suchlauf-Zeit: 13:13:38
Logdatei: mbm.txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.06.07.02
Rootkit Datenbank: v2015.06.02.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Dali
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 403642
Verstrichene Zeit: 37 Min, 44 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 21
PUP.Optional.Babylon.A, HKU\S-1-5-18\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, In Quarantäne, [dc02f3c43c4ed363b296fd69e51e2ed2],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{10A580BE-DF75-4944-9E15-0552BA38CBB2}, In Quarantäne, [00de2d8ae1a9082e47f0f68b2ed72ed2],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D1E00947-F971-464A-82E9-59191D89DE11}, In Quarantäne, [8757dfd8ed9dce6890a67d0413f2a957],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FA5A0D6A-1489-42CB-80F3-3B4701064B60}, In Quarantäne, [b826cceb5b2f2a0ca890790875903ac6],
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE, In Quarantäne, [02dc3d7a01897fb723f9750f7392e41c],
PUP.Optional.MediaWatch.A, HKLM\SOFTWARE\WOW6432NODE\MediaWatchV1home715, In Quarantäne, [805eb7001179fc3a4a6b01652fd6fc04],
PUP.Optional.FreeGames.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\lbgfiglojokgabdbhegbpjgojgppppgf, In Quarantäne, [c31b9e193951b680f5e678bfeb192dd3],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{10A580BE-DF75-4944-9E15-0552BA38CBB2}, In Quarantäne, [c7172295711995a156e15829c540ca36],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8217F88B-1E55-40E8-BA62-47713D36EB56}, In Quarantäne, [548a9f18612950e60531522fcc3954ac],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8D3F8D24-BA70-479E-863D-C41FBFF93799}, In Quarantäne, [e8f6e6d12a6086b03503057c8085f10f],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C7177BB1-9984-4004-98F3-2C9ABAB52865}, In Quarantäne, [05d9c6f1ff8b5ed871c6e0a1f114f20e],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D1E00947-F971-464A-82E9-59191D89DE11}, In Quarantäne, [03dbe0d74a4047efb581354ce91c29d7],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FA5A0D6A-1489-42CB-80F3-3B4701064B60}, In Quarantäne, [934b1c9b4d3d53e3fa3efe83d035f808],
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\UPDATE, In Quarantäne, [9e40c4f37317bf77ea32f3910ef752ae],
PUP.Optional.TornTV.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\Torntv V9.0, In Quarantäne, [9f3f7e39b0dac76f8680a68c699bf40c],
Malware.Trace, HKU\S-1-5-21-2150798412-3475795421-3249833344-1001\SOFTWARE\DC3_FEXEC, In Quarantäne, [4d91873092f8c670f0e6e8f15ea6e21e],
PUP.Optional.PlusHD.A, HKU\S-1-5-21-2150798412-3475795421-3249833344-1001\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-1.6, In Quarantäne, [607ec4f3345652e45ae505263ec6d62a],
PUP.Optional.TornTV.A, HKU\S-1-5-21-2150798412-3475795421-3249833344-1001\SOFTWARE\APPDATALOW\SOFTWARE\Torntv V9.0, In Quarantäne, [9a44e4d33d4d7db97195a290f50f52ae],
PUP.Optional.ReImageRepair.A, HKU\S-1-5-21-2150798412-3475795421-3249833344-1001\SOFTWARE\LOCAL APPWIZARD-GENERATED APPLICATIONS\Reimage - Windows Problem Relief., In Quarantäne, [a13df3c490fab581be386e16ce377b85],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2150798412-3475795421-3249833344-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5A431A54-ECB2-40A3-AA1F-2F2C66892E77}, In Quarantäne, [26b84572a5e53ff7c174631e0ff606fa],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2150798412-3475795421-3249833344-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7EE26399-48BA-4D30-9912-CB32575CD43E}, In Quarantäne, [4995c2f5ec9eb48289abf48dac59d22e],
Registrierungswerte: 16
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{10a580be-df75-4944-9e15-0552ba38cbb2}|AppName, Plus-HD-1.6-buttonutil.exe, In Quarantäne, [00de2d8ae1a9082e47f0f68b2ed72ed2]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{d1e00947-f971-464a-82e9-59191d89de11}|AppName, Plus-HD-1.6-bg.exe, In Quarantäne, [8757dfd8ed9dce6890a67d0413f2a957]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{fa5a0d6a-1489-42cb-80f3-3b4701064b60}|AppName, Plus-HD-1.6-codedownloader.exe, In Quarantäne, [b826cceb5b2f2a0ca890790875903ac6]
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, In Quarantäne, [02dc3d7a01897fb723f9750f7392e41c]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{10a580be-df75-4944-9e15-0552ba38cbb2}|AppName, Plus-HD-1.6-buttonutil.exe, In Quarantäne, [c7172295711995a156e15829c540ca36]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8217f88b-1e55-40e8-ba62-47713d36eb56}|AppName, Object Browser-bg.exe, In Quarantäne, [548a9f18612950e60531522fcc3954ac]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8d3f8d24-ba70-479e-863d-c41fbff93799}|AppName, Object Browser-codedownloader.exe, In Quarantäne, [e8f6e6d12a6086b03503057c8085f10f]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{c7177bb1-9984-4004-98f3-2c9abab52865}|AppName, Object Browser-buttonutil.exe, In Quarantäne, [05d9c6f1ff8b5ed871c6e0a1f114f20e]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{d1e00947-f971-464a-82e9-59191d89de11}|AppName, Plus-HD-1.6-bg.exe, In Quarantäne, [03dbe0d74a4047efb581354ce91c29d7]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{fa5a0d6a-1489-42cb-80f3-3b4701064b60}|AppName, Plus-HD-1.6-codedownloader.exe, In Quarantäne, [934b1c9b4d3d53e3fa3efe83d035f808]
PUP.Optional.QuickStart.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|quick_start@gmail.com, C:\Users\Dali\AppData\Roaming\Mozilla\Firefox\Profiles\kggn59xw.default\extensions\quick_start@gmail.com, In Quarantäne, [726c7146b7d3d462ec29ea42ec189b65]
PUP.Optional.MediaWatch.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|ext@MediaWatchV1home715.net, C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home715\ff, In Quarantäne, [984605b26b1f072f14a2570ff213df21]
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, In Quarantäne, [9e40c4f37317bf77ea32f3910ef752ae]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2150798412-3475795421-3249833344-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5A431A54-ECB2-40A3-AA1F-2F2C66892E77}|AppName, c9cfb475-3728-4a43-ab15-eea815d77c24-2.exe-codedownloader.exe, In Quarantäne, [26b84572a5e53ff7c174631e0ff606fa]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2150798412-3475795421-3249833344-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7EE26399-48BA-4D30-9912-CB32575CD43E}|AppName, c9cfb475-3728-4a43-ab15-eea815d77c24-2.exe-buttonutil.exe, In Quarantäne, [4995c2f5ec9eb48289abf48dac59d22e]
PUP.Optional.MarkIt.A, HKU\S-1-5-21-2150798412-3475795421-3249833344-1001\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{ca8d6db6-5602-4d27-ab28-25dd0eba8833}, C:\Program Files (x86)\Re-markit\150.xpi, In Quarantäne, [cd11cfe82466082eadb31d5d867f1be5]
Registrierungsdaten: 0
(Keine schädliche Elemente gefunden)
Ordner: 4
Stolen.Data, C:\Users\Dali\AppData\Roaming\dclogs, In Quarantäne, [7c627e39d4b669cded80709884817789],
PUP.Optional.Iminent.A, C:\Users\Dali\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl, In Quarantäne, [e0fe4374583287af743efabaa063ca36],
PUP.Optional.CrossRider.A, C:\Users\Dali\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\majjphhgppkndjjkmhhnbgafooenebhd, In Quarantäne, [39a5a80f6327340250ac2f8bdd26ab55],
PUP.Optional.CrossRider.A, C:\Users\Dali\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kfgaibfbmkjgmimhbbaikfnpkkjkpoan, In Quarantäne, [b32b97200486063078ef2597b251c13f],
Dateien: 8
PUP.Optional.InstalleRex.A, C:\ProgramData\InstallMate\{AEB2C5BC-A01B-47FC-A517-E8397551E74A}\Custom.dll, In Quarantäne, [637bb00767231e18cdb9c97c1ee2db25],
Backdoor.Agent.FR, C:\Users\Dali\Downloads\CSGO Key Hack v.3.7.rar, In Quarantäne, [2cb25661a4e6c076115061050cf6cc34],
PUP.Optional.ReMarkIt.A, C:\Windows\System32\Tasks\Re-markit Update, In Quarantäne, [ab33e1d613773afc4bafbf55818358a8],
PUP.Optional.ReMarkIt.A, C:\Windows\Tasks\Re-markit Update.job, In Quarantäne, [59859720e1a9231368e3909c40c45ea2],
Stolen.Data, C:\Users\Dali\AppData\Roaming\dclogs\2014-01-19-1.dc, In Quarantäne, [7c627e39d4b669cded80709884817789],
Stolen.Data, C:\Users\Dali\AppData\Roaming\dclogs\2014-02-22-7.dc, In Quarantäne, [7c627e39d4b669cded80709884817789],
Stolen.Data, C:\Users\Dali\AppData\Roaming\dclogs\2014-02-23-1.dc, In Quarantäne, [7c627e39d4b669cded80709884817789],
PUP.Optional.Iminent.A, C:\Users\Dali\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl\empty.localstorage, In Quarantäne, [e0fe4374583287af743efabaa063ca36],
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.8.9 (06.06.2015:1)
OS: Windows 7 Ultimate x64
Ran by Dali on 07.06.2015 at 13:11:17,67
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\\SearchAssistant
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-2150798412-3475795421-3249833344-1001\Software\Microsoft\Internet Explorer\Main\\Start Page
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440344204402}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440344204402}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440344204402}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440344204402}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110311281150}
~~~ Files
Successfully deleted: [File] C:\Windows\syswow64\wscm32.dll
Successfully deleted: [File] C:\Windows\syswow64\wscm64.dll
Successfully deleted: [File] C:\Users\Dali\appdata\local\nsfEB80.tmp
~~~ Folders
Successfully deleted: [Folder] C:\ProgramData\baidu
Successfully deleted: [Folder] C:\Users\Dali\appdata\local\crashrpt
Successfully deleted: [Folder] C:\Windows\syswow64\ai_recyclebin
Successfully deleted: [Folder] C:\ProgramData\SavENewAuAeppz [BHO.Multiplug]
Successfully deleted: [Folder] C:\ProgramData\SAvveLoTs [BHO.Multiplug]
~~~ Chrome
[C:\Users\Dali\appdata\local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
[C:\Users\Dali\appdata\local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
[C:\Users\Dali\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
[C:\Users\Dali\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[
iagcajndpnfncplednpbnkahadegklfa,
ifohbjbgfchkkfhphahclmkpgejiplfo,
ogfjmhfnldnajmfaofeiaepghjenbgjo
]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 07.06.2015 at 13:17:03,67
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
Shortcut Cleaner 1.3.8 by Lawrence Abrams (Grinler)
hxxp://www.bleepingcomputer.com/
Copyright 2008-2015 BleepingComputer.com
More Information about Shortcut Cleaner can be found at this link:
hxxp://www.bleepingcomputer.com/download/shortcut-cleaner/
Windows Version: Windows 7 Ultimate Service Pack 1
Program started at: 06/07/2015 02:00:04 PM.
Scanning for registry hijacks:
* No issues found in the Registry.
Searching for Hijacked Shortcuts:
Searching C:\Users\Dali\AppData\Roaming\Microsoft\Windows\Start Menu\
Searching C:\ProgramData\Microsoft\Windows\Start Menu\
Searching C:\Users\Dali\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\
Searching C:\Users\Public\Desktop\
Searching C:\Users\Dali\Desktop\
Searching C:\Users\Public\Desktop\
0 bad shortcuts found.
Program finished at: 06/07/2015 02:00:09 PM
Execution time: 0 hours(s), 0 minute(s), and 5 seconds(s)
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:06-06-2015
Ran by Dali (administrator) on DALI-PC on 07-06-2015 14:01:06
Running from C:\Users\Dali\Downloads
Loaded Profiles: Dali (Available Profiles: Dali)
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Skillbrains) C:\Program Files (x86)\Skillbrains\lightshot\5.2.0.17\Lightshot.exe
(ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDWare] => C:\Program Files\Elantech\ETDCtrl.exe [649608 2010-04-13] (ELAN Microelectronic Corp.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [728312 2015-05-05] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [DelaypluginInstall] => C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe [1960336 2014-11-21] ()
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2014-11-20] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [226560 2014-11-18] ()
HKU\S-1-5-21-2150798412-3475795421-3249833344-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2892992 2015-06-04] (Valve Corporation)
HKU\S-1-5-21-2150798412-3475795421-3249833344-1001\...\Policies\system: [DisableLockWorkstation] 0
AppInit_DLLs-x32: c:\progra~2\sn0310~1.boo => "c:\progra~2\sn0310~1.boo" File not found
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKU\S-1-5-21-2150798412-3475795421-3249833344-1001\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKU\S-1-5-21-2150798412-3475795421-3249833344-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://terra.im/
HKU\S-1-5-21-2150798412-3475795421-3249833344-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKU\S-1-5-21-2150798412-3475795421-3249833344-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://terra.im/
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2150798412-3475795421-3249833344-1001 -> {4187F0FC-AF41-4E4B-AE67-84C8FD35A0AE} URL = hxxp://terra.im/search?q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-02-20] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-20] (Oracle Corporation)
BHO-x32: Wondershare Video Converter Ultimate 7.1.0 -> {451C804F-C205-4F03-B48E-537EC94937BF} -> C:\ProgramData\Wondershare\Video Converter Ultimate\WSBrowserAppMgr.dll [2014-11-21] (Wondershare)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-02-20] (Oracle Corporation)
BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> C:\Program Files (x86)\Arc\plugins\ArcPluginIE.dll [2015-03-10] (Perfect World Entertainment Inc)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-20] (Oracle Corporation)
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
DPF: HKLM-x32 {0D41B8C5-2599-4893-8183-00195EC8D5F9} hxxp://support.asus.de/common/asusTek_sys_ctrl.cab
DPF: HKLM-x32 {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} https://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.96.0.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-15] ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.21.2 -> C:\Windows\system32\npDeployJava1.dll [2013-06-14] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-20] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll No File
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll No File
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-20] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-20] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
FF Plugin-x32: @ngm.nexoneu.com/NxGame -> C:\ProgramData\NexonEU\NGM\npNxGameEU.dll [2014-12-25] (Nexon)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> C:\Program Files (x86)\Arc\plugins\npArcPluginFF.dll [2015-03-10] (Perfect World Entertainment Inc)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-2150798412-3475795421-3249833344-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Dali\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF HKLM-x32\...\Firefox\Extensions: [WSVCU@Wondershare.com] - C:\ProgramData\Wondershare\Video Converter Ultimate\WSVCU@Wondershare.com
FF Extension: Wondershare Video Converter Ultimate - C:\ProgramData\Wondershare\Video Converter Ultimate\WSVCU@Wondershare.com [2014-12-04]
FF HKU\S-1-5-21-2150798412-3475795421-3249833344-1001\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff
Chrome:
=======
CHR Profile: C:\Users\Dali\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Adblock Plus) - C:\Users\Dali\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-10-22]
CHR Extension: (Lounge Assistant) - C:\Users\Dali\AppData\Local\Google\Chrome\User Data\Default\Extensions\enjonnlehciedbcidabdglnnihcncbml [2015-01-15]
CHR Extension: (Bookmark Manager) - C:\Users\Dali\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-16]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Dali\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-13]
CHR Extension: (Dingit Infinite HD App) - C:\Users\Dali\AppData\Local\Google\Chrome\User Data\Default\Extensions\llnhnfikffkjbdnfallfpgikamegbbag [2015-06-04]
CHR Extension: (Google Wallet) - C:\Users\Dali\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-14]
CHR Profile: C:\Users\Dali\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (sAve! net) - C:\Users\Dali\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ccambohcoplkadcfgjaiidcafghaneii [2014-05-03]
CHR Extension: (Adblock Plus) - C:\Users\Dali\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-04-13]
CHR Extension: (Tampermonkey) - C:\Users\Dali\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2014-03-11]
CHR Extension: (No Name) - C:\Users\Dali\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kfgaibfbmkjgmimhbbaikfnpkkjkpoan [2014-03-10]
CHR Extension: (Google Wallet) - C:\Users\Dali\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-28]
CHR Extension: (Battlefield Play4Free) - C:\Users\Dali\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oiokahphinmbmakkehgelkmpolmnbkdh [2014-03-13]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [827640 2015-05-05] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [434424 2015-05-05] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [434424 2015-05-05] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1185584 2015-05-05] (Avira Operations GmbH & Co. KG)
S3 ArcService; C:\Program Files (x86)\Arc\ArcService.exe [88400 2015-03-10] (Perfect World Entertainment Inc)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-02-25] ()
S4 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AtiDCM; C:\Users\Dali\AppData\Local\Temp\atdcm64a.sys [28896 2014-04-18] (Advanced Micro Devices, Inc.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [148792 2013-09-25] (AVG Technologies CZ, s.r.o.)
R1 Avgfwfd; C:\Windows\System32\DRIVERS\avgfwd6a.sys [57144 2013-09-26] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [241464 2013-09-02] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [192824 2013-09-02] (AVG Technologies CZ, s.r.o.)
S1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-09-02] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-09-02] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-08-20] (AVG Technologies CZ, s.r.o.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [152744 2015-05-05] (Avira Operations GmbH & Co. KG)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-08] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [251192 2013-08-01] (AVG Technologies CZ, s.r.o.)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132120 2015-05-05] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-06-24] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [44088 2015-03-04] (Avira Operations GmbH & Co. KG)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-04-14] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ATK64AMD.sys [13680 2007-08-09] ()
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
R1 RrNetCapFilterDriver; C:\Windows\System32\DRIVERS\RrNetCapFilterDriver.sys [24744 2014-11-19] (Audials AG)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800192 2009-08-20] ()
S3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2014-05-17] (Anchorfree Inc.)
S3 tapoas; C:\Windows\System32\DRIVERS\tapoas.sys [30720 2012-07-15] (The OpenVPN Project)
S3 tapSF0901; C:\Windows\System32\DRIVERS\tapSF0901.sys [39104 2014-04-05] (Spotflux, Inc.)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2012-12-13] (Apple, Inc.) [File not signed]
S3 cpuz134; \??\C:\Users\Dali\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S1 wcrxcinz; \??\C:\Windows\system32\drivers\wcrxcinz.sys [X]
S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-07 14:00 - 2015-06-07 14:00 - 00001860 _____ C:\Users\Dali\Desktop\sc-cleaner.txt
2015-06-07 13:59 - 2015-06-07 13:59 - 00463688 _____ (Bleeping Computer, LLC) C:\Users\Dali\Downloads\sc-cleaner (1).exe
2015-06-07 13:57 - 2015-06-07 13:57 - 00010315 _____ C:\Users\Dali\Desktop\mbm.txt
2015-06-07 13:53 - 2015-06-07 13:53 - 00003594 _____ C:\Windows\PFRO.log
2015-06-07 13:17 - 2015-06-07 13:17 - 00003172 _____ C:\Users\Dali\Desktop\JRT.txt
2015-06-07 13:11 - 2015-06-07 13:11 - 00000207 _____ C:\Windows\tweaking.com-regbackup-DALI-PC-Windows-7-Ultimate-(64-bit).dat
2015-06-07 13:11 - 2015-06-07 13:11 - 00000000 ____D C:\RegBackup
2015-06-07 13:02 - 2015-06-07 13:56 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-06-07 13:02 - 2015-06-07 13:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-06-07 13:02 - 2015-06-07 13:02 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-06-07 13:02 - 2015-06-07 13:02 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-06-07 13:02 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-06-07 13:02 - 2015-04-14 09:37 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-06-07 13:02 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-06-07 13:01 - 2015-06-07 13:01 - 02942406 _____ (Thisisu) C:\Users\Dali\Downloads\JRT.exe
2015-06-07 13:00 - 2015-06-07 13:01 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Dali\Downloads\mbam-setup-2.1.6.1022.exe
2015-06-07 13:00 - 2015-06-07 13:01 - 00463688 _____ (Bleeping Computer, LLC) C:\Users\Dali\Downloads\sc-cleaner.exe
2015-06-07 12:50 - 2015-06-07 12:51 - 00031430 _____ C:\Users\Dali\Desktop\AdwCleaner[S0].txt
2015-06-07 12:47 - 2015-06-07 13:00 - 00000000 ____D C:\AdwCleaner
2015-06-07 12:46 - 2015-06-07 12:46 - 02231296 _____ C:\Users\Dali\Downloads\AdwCleaner_4.206.exe
2015-06-06 16:00 - 2015-06-06 16:00 - 04197016 _____ (Kaspersky Lab ZAO) C:\Users\Dali\Downloads\tdsskiller.exe
2015-06-06 15:47 - 2015-06-06 15:50 - 00060442 _____ C:\Users\Dali\Downloads\Addition.txt
2015-06-06 15:41 - 2015-06-07 14:01 - 00018048 _____ C:\Users\Dali\Downloads\FRST.txt
2015-06-06 15:41 - 2015-06-07 14:01 - 00000000 ____D C:\FRST
2015-06-06 15:40 - 2015-06-06 15:40 - 02108928 _____ (Farbar) C:\Users\Dali\Downloads\FRST64.exe
2015-06-05 22:48 - 2015-06-05 23:09 - 00000000 ____D C:\EEK
2015-06-03 00:01 - 2015-06-03 00:01 - 00008848 _____ C:\Users\Dali\AppData\Local\recently-used.xbel
2015-06-02 23:38 - 2015-06-02 23:38 - 14639556 _____ C:\Users\Dali\Downloads\CsP.rar
2015-06-01 00:52 - 2015-06-01 00:52 - 00015473 _____ C:\Users\Dali\Downloads\CSGO TeamSpeak Rank Icons.zip
2015-05-31 21:43 - 2015-05-31 21:43 - 00000000 ____D C:\Program Files (x86)\FreeTime
2015-05-27 11:07 - 2015-05-27 11:07 - 00115584 _____ C:\Users\Dali\AppData\Local\GDIPFONTCACHEV1.DAT
2015-05-27 11:05 - 2015-05-27 11:06 - 05080808 _____ C:\Windows\system32\FNTCACHE.DAT
2015-05-27 00:18 - 2015-06-07 13:53 - 00004312 _____ C:\Windows\setupact.log
2015-05-27 00:18 - 2015-05-27 00:18 - 00000000 _____ C:\Windows\setuperr.log
2015-05-23 19:39 - 2015-05-23 19:39 - 00000000 ____D C:\Users\Dali\AppData\Local\VetoClient
2015-05-23 19:38 - 2015-05-23 19:38 - 00000150 _____ C:\Users\Dali\Downloads\maps.txt
2015-05-23 19:24 - 2015-05-23 19:25 - 00218624 _____ C:\Users\Dali\Downloads\Mapvote.exe
2015-05-23 19:23 - 2015-05-23 19:23 - 00020480 _____ C:\Users\Dali\Downloads\VetoClient.exe
2015-05-23 12:13 - 2015-05-23 12:13 - 00011868 _____ C:\Users\Dali\Downloads\[www.OldSchoolHack.de]_MadHack V0.9B.zip
2015-05-11 19:15 - 2015-05-11 19:15 - 01413824 _____ C:\Users\Dali\Downloads\L2ra.bun
2015-05-11 19:15 - 2015-05-11 19:15 - 00000000 _____ C:\Users\Dali\Downloads\Loc2dyntex.bin
2015-05-11 19:14 - 2015-05-11 19:14 - 00013575 _____ C:\Users\Dali\Downloads\Precullerboobooscript.hoo
2015-05-09 22:20 - 2015-05-09 22:20 - 00000000 ____D C:\ProgramData\WEBZEN
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-07 13:57 - 2013-04-18 06:34 - 01912295 _____ C:\Windows\WindowsUpdate.log
2015-06-07 13:56 - 2015-03-26 17:18 - 00000000 ____D C:\Program Files (x86)\Steam
2015-06-07 13:54 - 2013-05-01 14:49 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-07 13:53 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-07 13:31 - 2013-05-01 14:49 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-07 13:18 - 2013-04-18 06:40 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-06-07 13:01 - 2009-07-14 06:45 - 00026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-07 13:01 - 2009-07-14 06:45 - 00026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-07 12:50 - 2013-04-26 18:45 - 00000924 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2150798412-3475795421-3249833344-1001UA.job
2015-06-06 21:22 - 2013-04-18 19:57 - 00000000 ____D C:\Users\Dali\AppData\Roaming\TS3Client
2015-06-06 18:50 - 2013-04-26 18:45 - 00000902 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2150798412-3475795421-3249833344-1001Core.job
2015-06-06 04:00 - 2014-09-22 17:21 - 00000000 ____D C:\Program Files (x86)\MTA San Andreas 1.4
2015-06-06 04:00 - 2014-08-15 23:44 - 00000000 ____D C:\ProgramData\MTA San Andreas All
2015-06-06 04:00 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-06-05 23:11 - 2013-04-18 06:34 - 00000000 ____D C:\Users\Dali
2015-06-05 23:10 - 2013-04-18 19:55 - 00000000 ____D C:\Users\Dali\AppData\Local\TeamSpeak 3 Client
2015-06-05 23:09 - 2014-01-19 02:29 - 00000000 ____D C:\Users\Dali\AppData\Local\gtk-2.0
2015-06-05 23:09 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2015-06-05 23:09 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\AppCompat
2015-06-04 17:37 - 2013-06-15 08:15 - 00000000 ____D C:\Users\Dali\AppData\Local\Adobe
2015-06-03 00:18 - 2014-01-19 02:24 - 00000000 ____D C:\Users\Dali\.gimp-2.8
2015-05-31 21:46 - 2013-07-21 16:17 - 00000000 ____D C:\FFOutput
2015-05-28 12:48 - 2011-04-12 09:43 - 00737110 _____ C:\Windows\system32\perfh007.dat
2015-05-28 12:48 - 2011-04-12 09:43 - 00163958 _____ C:\Windows\system32\perfc007.dat
2015-05-28 12:48 - 2009-07-14 07:13 - 01708588 _____ C:\Windows\system32\PerfStringBackup.INI
2015-05-26 22:51 - 2015-04-27 17:47 - 00000000 ____D C:\Program Files (x86)\Hearthstone
2015-05-26 22:50 - 2015-04-27 17:38 - 00000000 ____D C:\Users\Dali\AppData\Local\Battle.net
2015-05-26 22:50 - 2015-04-27 17:37 - 00000000 ____D C:\Program Files (x86)\Battle.net
2015-05-16 09:26 - 2013-05-01 14:49 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-05-16 09:25 - 2013-05-01 14:49 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-05-09 23:12 - 2013-06-29 10:45 - 00000000 ____D C:\Download
==================== Files in the root of some directories =======
2014-04-28 20:28 - 2014-04-28 20:28 - 0000112 _____ () C:\Users\Dali\AppData\Roaming\JP2K CS6 Prefs
2014-04-14 13:52 - 2014-04-14 13:52 - 0000043 _____ () C:\Users\Dali\AppData\Roaming\WB.CFG
2014-05-04 00:05 - 2014-05-04 00:05 - 0000000 ___SH () C:\Users\Dali\AppData\Local\LumaEmu
2015-06-03 00:01 - 2015-06-03 00:01 - 0008848 _____ () C:\Users\Dali\AppData\Local\recently-used.xbel
2013-07-01 19:02 - 2014-05-31 16:14 - 0007597 _____ () C:\Users\Dali\AppData\Local\resmon.resmoncfg
2015-01-16 01:40 - 2015-01-16 01:40 - 0000003 _____ () C:\Users\Dali\AppData\Local\updater.log
2015-01-16 01:40 - 2015-01-19 01:18 - 0000425 _____ () C:\Users\Dali\AppData\Local\UserProducts.xml
Some files in TEMP:
====================
C:\Users\Dali\AppData\Local\Temp\avgnt.exe
C:\Users\Dali\AppData\Local\Temp\Quarantine.exe
C:\Users\Dali\AppData\Local\Temp\SpotifyUninstall.exe
C:\Users\Dali\AppData\Local\Temp\sqlite3.dll
C:\Users\Dali\AppData\Local\Temp\tmd_34016735.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-06-03 07:40
==================== End of log ============================ --- --- ---
[CODE]Additional
FRST Logfile: Code:
scan result of Farbar Recovery Scan Tool (x64) Version:06-06-2015
Ran by Dali at 2015-06-07 14:02:07
Running from C:\Users\Dali\Downloads
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2150798412-3475795421-3249833344-500 - Administrator - Disabled)
Dali (S-1-5-21-2150798412-3475795421-3249833344-1001 - Administrator - Enabled) => C:\Users\Dali
Gast (S-1-5-21-2150798412-3475795421-3249833344-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2150798412-3475795421-3249833344-1002 - Limited - Enabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Antivirus (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Antivirus (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Aeria Ignite (HKLM-x32\...\Aeria Ignite) (Version: 1.13.3296 - Aeria Games & Entertainment)
Aeria Ignite (x32 Version: 1.13.3296 - Aeria Games & Entertainment) Hidden
AION Free-to-Play (HKLM-x32\...\{82E73E8D-E1E7-45A4-A311-6D31492AA913}_is1) (Version: - Gameforge)
AMD Catalyst Install Manager (HKLM\...\{F2A7CE36-57BF-5C86-952D-90DBF3746D82}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Arc (HKLM-x32\...\{CED8E25B-122A-4E80-B612-7F99B93284B3}) (Version: 1.0.0.9668 - Perfect World Entertainment)
Audials (HKLM-x32\...\{A7207DE0-6320-4585-8335-63B24247EE7D}) (Version: 12.0.55701.100 - Audials AG)
AVG 2014 (Version: 14.0.3614 - AVG Technologies) Hidden
AVG 2014 (Version: 14.0.4158 - AVG Technologies) Hidden
AVG PC TuneUp (x32 Version: 12.0.4000.108 - AVG Technologies) Hidden
AVG PC TuneUp Language Pack (de-DE) (x32 Version: 12.0.4000.108 - AVG Technologies) Hidden
Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.10.434 - Avira Operations GmbH & Co. KG)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
CCleaner (HKLM\...\CCleaner) (Version: 4.08 - Piriform)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Disk Space Fan 4 Free 4.5.1.129 (HKLM-x32\...\Disk Space Fan 4 Free_is1) (Version: - Disk Space Fan Team)
DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.7.0.64 - DivX, LLC)
Eden4SDE version 33852 (HKLM-x32\...\{6C918475-3898-4192-81D4-E083A3DAA871}_is1) (Version: 33852 - Eden4S, Inc.)
ETDWare PS/2-x64 7.0.5.11_WHQL (HKLM\...\Elantech) (Version: 7.0.5.11 - ELAN Microelectronics Corp.)
Facebook Video Calling 2.0.0.447 (HKLM-x32\...\{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}) (Version: 2.0.447 - Skype Limited)
Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Fraps (remove only) (HKLM-x32\...\Fraps) (Version: - )
Free YouTube Download version 3.2.56.324 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.56.324 - DVDVideoSoft Ltd.)
Gameforge Live 2.0.6 (HKLM-x32\...\{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1) (Version: 2.0.6 - Gameforge)
GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.81 - Google Inc.)
Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
Google+ Auto Backup (HKLM-x32\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment)
Java 8 Update 31 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418031F0}) (Version: 8.0.310 - Oracle Corporation)
Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
JMicron Ethernet Adapter NDIS Driver (HKLM-x32\...\{96DCEE2F-98EE-4F80-8C0F-7C04D1FB9D7F}) (Version: 6.0.27.6 - JMicron Technology Corp.)
JMicron Flash Media Controller Driver (HKLM-x32\...\{26604C7E-A313-4D12-867F-7C6E7820BE4C}) (Version: 1.0.33.2 - JMicron Technology Corp.)
Lagarith Lossless Codec (1.3.27) (HKLM-x32\...\{F59AC46C-10C3-4023-882C-4212A92283B3}_is1) (Version: - )
Lightshot-5.2.0.17 (HKLM-x32\...\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1) (Version: 5.2.0.17 - Skillbrains)
MAGIX Video deluxe 2014 (HKLM-x32\...\MX.{EA62B22F-AB0A-406B-80A9-8036D3CE3446}) (Version: 13.0.0.30 - MAGIX AG)
MAGIX Video deluxe 2014 (Version: 13.0.0.30 - MAGIX AG) Hidden
Malwarebytes Anti-Malware Version 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Virtual PC 2007 SP1 (HKLM\...\{AD483998-2E9A-4405-83FF-6E503AF49CBB}) (Version: 6.0.192.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{b341426f-8543-4e0d-96c3-e976f8ec5ab6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 30.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
NVIDIA PhysX (HKLM-x32\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
OpenOffice 4.1.1 (HKLM-x32\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation)
Paint.NET v3.5.11 (HKLM\...\{72EF03F5-0507-4861-9A44-D99FD4C41418}) (Version: 3.61.0 - dotPDN LLC)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
QuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
Rapture3D 2.4.11 Game (HKLM-x32\...\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1) (Version: - Blue Ripple Sound)
Security Task Manager 2.0d (HKLM-x32\...\Security Task Manager) (Version: 2.0d - Neuber Software)
Shutdown Timer (HKLM\...\{0B1BBEE3-C10D-44BE-A6BE-EEC867315F87}) (Version: 3.3.4 - Sinvise Systems)
Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
SpyHunter (HKLM\...\{ACF5FE1B-3772-4068-8B87-2D2A6EFD0A05}) (Version: 4.17.6.4336 - Enigma Software Group USA, LLC)
Startfenster (HKLM-x32\...\Startfenster) (Version: - Startfenster)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
System Requirements Lab (HKLM-x32\...\{B35DBBD7-B42E-494A-8913-431A2E448131}) (Version: 6.1.1.0 - Husdawg, LLC)
TAP-Windows 9.9.2 (HKLM\...\TAP-Windows) (Version: 9.9.2 - )
TeamSpeak 3 Client (HKU\S-1-5-21-2150798412-3475795421-3249833344-1001\...\TeamSpeak 3 Client) (Version: 3.0.15 - TeamSpeak Systems GmbH)
USB2.0 UVC VGA WebCam (HKLM\...\USB2.0 UVC VGA WebCam) (Version: 5.8.54000.207 - Sonix)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Virtual Audio Cable 4.10 (HKLM\...\Virtual Audio Cable 4.10) (Version: - )
VirtualDJ Home FREE (HKLM-x32\...\{77C2D5D4-ADC5-49F9-B36E-5992FCF35EA3}) (Version: 7.4.1 - Atomix Productions)
VirtualDJ PRO Full (HKLM-x32\...\{4769E972-2E92-49C5-B6F9-465EFD0C4D94}) (Version: 7.0.5 - Atomix Productions)
Visual Studio 2010 x64 Redistributables (HKLM\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VPNAutoconnect (HKLM-x32\...\{8E557F21-99AE-440D-8058-CD8CB3302E13}) (Version: 1.15 - globalip)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
WinRAR 5.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2150798412-3475795421-3249833344-1001_Classes\CLSID\{087B3AE3-E237-4467-B8DB-5A38AB959AC9}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2150798412-3475795421-3249833344-1001_Classes\CLSID\{3B092F0C-7696-40E3-A80F-68D74DA84210}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2150798412-3475795421-3249833344-1001_Classes\CLSID\{63542C48-9552-494A-84F7-73AA6A7C99C1}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2150798412-3475795421-3249833344-1001_Classes\CLSID\{7BC0E710-5703-45BE-A29D-5D46D8B39262}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\ooofilt_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2150798412-3475795421-3249833344-1001_Classes\CLSID\{8932AEFE-9DB6-4f43-AFB2-5682F55E773A}\InprocServer32 -> C:\Program Files (x86)\Microsoft Virtual PC\VPCShExH.DLL (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2150798412-3475795421-3249833344-1001_Classes\CLSID\{AE424E85-F6DF-4910-A6A9-438797986431}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\propertyhdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2150798412-3475795421-3249833344-1001_Classes\CLSID\{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)
==================== Restore Points =========================
05-06-2015 23:00:41 Wiederherstellungsvorgang
06-06-2015 04:00:55 Removed Shutdown Timer.
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2013-11-15 18:39 - 00000853 ____N C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0141608A-4D7B-4A22-93BF-563ED59556AF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-05-01] (Google Inc.)
Task: {0A97BD66-B503-429A-9B4E-D8B60C2E088D} - System32\Tasks\{D5A75ACE-7787-4CBB-8E78-431F848DAF16} => pcalua.exe -a D:\SETUP.EXE -d D:\
Task: {0C20993A-76C6-445C-8858-794FBFA3D8B2} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2150798412-3475795421-3249833344-1001Core => C:\Users\Dali\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-04-26] (Facebook Inc.)
Task: {0E1D8BBA-C3C5-43F9-A3CC-675A77088715} - \Microsoft\Windows\Wininet\CacheTask No Task File <==== ATTENTION
Task: {1DFCD815-7C2A-455E-A657-43AEE5FC7501} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe
Task: {3CF2E20E-D36A-47C3-B0E9-7101569D3CDE} - System32\Tasks\{1D8DE8FA-71A4-4341-ADDE-9F0316331277} => pcalua.exe -a C:\Users\Dali\Desktop\setup.exe -d C:\Users\Dali\Desktop
Task: {43B0921D-CB75-4C25-B6A7-FC3C8F95FF7C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-11-22] (Piriform Ltd)
Task: {6B1C2579-03E5-4687-8F89-11949D8E474E} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-12-17] (Oracle Corporation)
Task: {6B81989E-8866-42E9-83F0-EFFD17972539} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012 => C:\Program Files (x86)\AVG\AVG PC TuneUp\OneClick.exe
Task: {7B8FFE88-DACD-44C1-8157-4CF9D241EC08} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe
Task: {8397A18E-F0BE-4752-9366-F003B63BC3FE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-15] (Adobe Systems Incorporated)
Task: {89D1425E-9892-4FAE-8436-959038AC2A0D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-05-01] (Google Inc.)
Task: {9A8ED8AD-79C7-4CD9-B16D-1340DDEB841C} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2150798412-3475795421-3249833344-1001UA => C:\Users\Dali\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-04-26] (Facebook Inc.)
Task: {B3E8C92C-9C49-42FF-81F6-C4F4AA32E5F3} - System32\Tasks\{4B7A6241-7421-4941-9351-C1C7F0C0B5F7} => pcalua.exe -a "C:\Users\Dali\AppData\Local\TeamSpeak 3 Client\package_inst.exe" -d C:\Users\Dali\Downloads -c "C:\Users\Dali\Downloads\blackops2_skin_2.ts3_style"
Task: {BFCDF6DD-C231-42EF-9A6A-9600B38DD91F} - System32\Tasks\{145A0961-95EC-44DB-8B59-3C6D2D8DCF98} => pcalua.exe -a C:\Users\Dali\Downloads\4StoryEG2011.exe -d C:\Users\Dali\Downloads
Task: {D3E93DF0-ACDB-4038-A01F-49D62BAC405E} - System32\Tasks\SidebarExecute => C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2010-11-21] (Microsoft Corporation)
Task: {DA23A690-5ECA-4D11-8DFA-16284B2AC305} - System32\Tasks\{7D58DF90-71A3-42CC-AF2A-4267335590F4} => pcalua.exe -a "C:\Program Files (x86)\Torntv V9.0\Uninstall.exe" -c /fcp=1
Task: {EB13ACB0-A0D2-4FDA-B6C6-C1A0730450E1} - System32\Tasks\Game_Booster_AutoUpdate => C:\Program Files (x86)\IObit\Game Booster 3\AutoUpdate.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2150798412-3475795421-3249833344-1001Core.job => C:\Users\Dali\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2150798412-3475795421-3249833344-1001UA.job => C:\Users\Dali\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\newSI_23.job => C:\Users\Dali\AppData\Roaming\newSI_23\s_inst.exe
==================== Loaded Modules (Whitelisted) ==============
2013-04-18 20:22 - 2014-02-25 21:54 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2010-01-02 16:42 - 2010-01-02 16:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
2015-05-25 21:41 - 2015-05-22 22:22 - 01281864 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.81\libglesv2.dll
2015-05-25 21:41 - 2015-05-22 22:22 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.81\libegl.dll
2015-05-25 21:41 - 2015-05-22 22:22 - 14982472 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.81\PepperFlash\pepflashplayer.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\ProgramData:NT
AlternateDataStreams: C:\ProgramData:NT2
AlternateDataStreams: C:\Users\All Users:NT
AlternateDataStreams: C:\Users\All Users:NT2
AlternateDataStreams: C:\ProgramData\Anwendungsdaten:NT
AlternateDataStreams: C:\ProgramData\Anwendungsdaten:NT2
AlternateDataStreams: C:\ProgramData\Application Data:NT
AlternateDataStreams: C:\ProgramData\Application Data:NT2
AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT
AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT2
AlternateDataStreams: C:\Users\Dali\Anwendungsdaten:NT
AlternateDataStreams: C:\Users\Dali\Anwendungsdaten:NT2
AlternateDataStreams: C:\Users\Dali\AppData\Roaming:NT
AlternateDataStreams: C:\Users\Dali\AppData\Roaming:NT2
==================== Safe Mode (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-2150798412-3475795421-3249833344-1001\...\aeriagames.com -> hxxps://aeriagames.com
IE trusted site: HKU\S-1-5-21-2150798412-3475795421-3249833344-1001\...\aeriagames.com -> hxxp://aeriagames.com
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2150798412-3475795421-3249833344-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Dali\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.2.1
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\Services: Apple Mobile Device => 2
MSCONFIG\Services: BDESVC => 3
MSCONFIG\Services: BEService => 3
MSCONFIG\Services: CGVPNCliService => 2
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: OverwolfUpdater => 3
MSCONFIG\Services: rpcapd => 3
MSCONFIG\Services: RzKLService => 2
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\Services: winzipersvc => 2
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^simplicheck.lnk => C:\Windows\pss\simplicheck.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Dali^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^lollipop.lnk => C:\Windows\pss\lollipop.lnk.Startup
MSCONFIG\startupreg: 4StoryPrePatch => C:\Program Files (x86)\GameforgeLive\Games\DEU_deu\4Story\PrePatch.exe
MSCONFIG\startupreg: Adobe Creative Cloud => "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
MSCONFIG\startupreg: Akamai NetSession Interface => "C:\Users\Dali\AppData\Local\Akamai\netsession_win.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: AVG_UI => "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
MSCONFIG\startupreg: BitTorrent => "C:\Users\Dali\AppData\Roaming\BitTorrent\BitTorrent.exe" /MINIMIZED
MSCONFIG\startupreg: CyberGhost => "C:\Program Files\CyberGhost 5\CyberGhost.EXE" /autostart
MSCONFIG\startupreg: DivXMediaServer => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
MSCONFIG\startupreg: Facebook Update => "C:\Users\Dali\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: LogMeIn Hamachi Ui => "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
MSCONFIG\startupreg: Overwolf => C:\Program Files (x86)\Overwolf\Overwolf.exe -silent
MSCONFIG\startupreg: Pando Media Booster => C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: Raptr => "C:\Program Files (x86)\Raptr\raptrstub.exe" --startup
MSCONFIG\startupreg: RazerGameBooster => C:\Program Files (x86)\Razer\Razer Game Booster\RazerGameBooster.exe -autorun
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: Spotify => "C:\Users\Dali\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart
MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\Dali\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: Wondershare Helper Compact.exe => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
MSCONFIG\startupreg: Wondershare Media Server => C:\Program Files (x86)\Wondershare\Video Converter Ultimate\MediaLibServer.exe
MSCONFIG\startupreg: XMouseButtonControl => C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonControl.exe /notportable
MSCONFIG\startupreg: YTDownloader => C:\Program Files (x86)\YTDownloader\YTDownloader.exe /boot
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [TCP Query User{907A3A8D-EDA1-443E-A26D-1F945E3D906B}C:\windows\syswow64\javaw.exe] => (Allow) C:\windows\syswow64\javaw.exe
FirewallRules: [UDP Query User{EE539585-3B3E-442F-9456-D42C47E7E1F4}C:\windows\syswow64\javaw.exe] => (Allow) C:\windows\syswow64\javaw.exe
FirewallRules: [{67DCAF7A-C2AD-47DC-A95D-C28AB744183A}] => (Allow) C:\ProgramData\NexonEU\NGM\NGM.exe
FirewallRules: [{35FAABF1-CDE2-49FB-8B17-DA475082BEA4}] => (Allow) C:\ProgramData\NexonEU\NGM\NGM.exe
FirewallRules: [TCP Query User{46BF264D-E9D3-4E8B-8D90-C8F3AE1D1A9E}C:\windows\system32\java.exe] => (Allow) C:\windows\system32\java.exe
FirewallRules: [UDP Query User{EEF2C4A1-7258-43D5-86DD-1AC4257270FE}C:\windows\system32\java.exe] => (Allow) C:\windows\system32\java.exe
FirewallRules: [{3A466375-B29B-4781-844F-ACB5B54AA8D2}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{9EB4995C-C91C-4FB1-8FFA-012D884C26F8}] => (Allow) LPort=2869
FirewallRules: [{2E6E8979-CCAC-49E1-A146-58D8E231D383}] => (Allow) LPort=1900
FirewallRules: [{78668624-77E0-4B02-8F0F-9A3835C62494}] => (Allow) LPort=80
FirewallRules: [{E3F2F8A2-7402-44CF-93A7-6849A6CE9C48}] => (Allow) LPort=443
FirewallRules: [{FDDF4FA5-39A4-4FD4-9FDC-45BC5755E73F}] => (Allow) LPort=20010
FirewallRules: [{AD5CF328-2118-4495-8932-457F8FBACF09}] => (Allow) LPort=3478
FirewallRules: [{8A863E1C-9135-46F5-B2D2-C61B52A37D5D}] => (Allow) LPort=7850
FirewallRules: [{3A09EF65-9EB0-4F75-A164-1BF10FEA8D9C}] => (Allow) LPort=27022
FirewallRules: [{345746E7-6F59-49F8-A199-5930373C1270}] => (Allow) LPort=6881
FirewallRules: [{A35BCC8C-3B7F-4EA3-820C-D1E5ADEFD5FC}] => (Allow) LPort=33333
FirewallRules: [{2C0429CA-DB34-431D-8DF7-80494A751644}] => (Allow) LPort=20443
FirewallRules: [{E8B2029F-ED78-44D4-8EC7-668E85253DE9}] => (Allow) LPort=8090
FirewallRules: [{941E05C9-8B68-4CA4-A3FF-77EFED3B9566}] => (Allow) C:\Users\Dali\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe
FirewallRules: [{95115294-8E74-4331-837C-470E8CE9C9C9}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{D13A11B3-8EE9-4E59-9BE9-3B42F3D898C2}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{F1502501-E847-4D30-8574-F9A314ECFD51}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{FD31B9A1-A329-4656-BAEF-0388758E74FD}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{89190396-0A50-47AA-83BA-2E42635D6175}] => (Allow) LPort=7852
FirewallRules: [{DE6177D1-87B0-4362-8471-6D7C9DE8A283}] => (Allow) LPort=7853
FirewallRules: [TCP Query User{56B7B527-91BA-4894-9912-04AABA71981B}C:\users\dali\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\dali\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{2FA31D39-0523-4D3E-A200-FC5391E087F2}C:\users\dali\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\dali\appdata\roaming\spotify\spotify.exe
FirewallRules: [{B6AF9F3D-9EBC-479D-818B-F5B9FC280CFC}] => (Allow) C:\Users\Dali\AppData\Roaming\Spotify\spotify.exe
FirewallRules: [{5A97002C-34EA-44FC-B20D-46FAC2BAE569}] => (Allow) C:\Users\Dali\AppData\Roaming\Spotify\spotify.exe
FirewallRules: [{AB467181-1BC2-4241-B93A-5BB24022908C}] => (Allow) LPort=12972
FirewallRules: [{B1A46735-ACB7-4B85-B508-B93B605C5DF2}] => (Allow) LPort=14714
FirewallRules: [{D6CFF3B9-0189-4EFD-BB0C-822AB0D54583}] => (Allow) LPort=31931
FirewallRules: [{9087BC92-DF80-4A0E-AA2E-B7AF52A35D14}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{03E1A0ED-F798-43E5-AD74-A428A33F3535}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{90D6F8F6-2982-4C2B-AE33-B3EC2AAF3DEA}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{7BB55E4A-0169-49A9-A2C6-9773298A3E97}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{2C749265-B6D8-4D74-9B6B-2B271C62EECB}] => (Allow) C:\Program Files (x86)\GameforgeLive\gfl_client.exe
FirewallRules: [{16439336-AD7B-4FE4-926D-25F164A55956}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{08B1C024-BCE4-4464-AEDB-AD7561D9F877}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [TCP Query User{F4263227-D356-4A8A-B86C-191C49B37DD8}C:\program files (x86)\gameforgelive\games\deu_deu\aion\nclauncher.exe] => (Allow) C:\program files (x86)\gameforgelive\games\deu_deu\aion\nclauncher.exe
FirewallRules: [UDP Query User{921C4874-91FA-45E4-9921-973EF4052D0A}C:\program files (x86)\gameforgelive\games\deu_deu\aion\nclauncher.exe] => (Allow) C:\program files (x86)\gameforgelive\games\deu_deu\aion\nclauncher.exe
FirewallRules: [{B2E2D16B-4439-4931-BB56-17B91558C27C}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{3F7C849C-3530-47E1-A5F3-D15B42DF5051}C:\program files (x86)\neverwinter_de\neverwinter\live\gameclient.exe] => (Allow) C:\program files (x86)\neverwinter_de\neverwinter\live\gameclient.exe
FirewallRules: [UDP Query User{066EC2C6-7860-4BFF-9B56-1ED6C41206F4}C:\program files (x86)\neverwinter_de\neverwinter\live\gameclient.exe] => (Allow) C:\program files (x86)\neverwinter_de\neverwinter\live\gameclient.exe
FirewallRules: [{F75B222E-DB46-4499-AAB2-A395ACD5349D}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{FF5DAA93-8064-40A8-B095-F9FD198A5002}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{E17C6E05-28CF-4350-BC2F-E26E259D4B7F}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{7AAE6AE8-B06C-40E2-B6BB-E6079DAAED1D}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{BDFC11C3-87EE-4140-9257-55221F2D6EDD}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Orbitdownloader\orbitdm.exe] => Enabled:Orbit
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Orbitdownloader\orbitnet.exe] => Enabled:Orbit
==================== Faulty Device Manager Devices =============
Name: Virtual Audio Cable
Description: Virtual Audio Cable
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: EuMus Design
Service: EuMusDesignVirtualAudioCableWdm
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
Name: TAP-Win32 Adapter V9 (Tunngle)
Description: TAP-Win32 Adapter V9 (Tunngle)
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: TAP-Win32 Provider V9 (Tunngle)
Service: tap0901t
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
Name: TAP-Windows Adapter V9
Description: TAP-Windows Adapter V9
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: TAP-Windows Provider V9
Service: tap0901
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (06/07/2015 02:37:43 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Steam.exe, Version: 2.81.34.6, Zeitstempel: 0x55708ca6
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x099aab30
ID des fehlerhaften Prozesses: 0x880
Startzeit der fehlerhaften Anwendung: 0xSteam.exe0
Pfad der fehlerhaften Anwendung: Steam.exe1
Pfad des fehlerhaften Moduls: Steam.exe2
Berichtskennung: Steam.exe3
Error: (06/06/2015 03:53:47 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm FRST64.exe, Version 6.6.2015.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: bc4
Startzeit: 01d0a05e75a63bfd
Endzeit: 8
Anwendungspfad: C:\Users\Dali\Downloads\FRST64.exe
Berichts-ID:
Error: (06/06/2015 02:59:07 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: steamwebhelper.exe, Version: 2.81.34.6, Zeitstempel: 0x55708c89
Name des fehlerhaften Moduls: libcef.dll, Version: 3.2272.30.0, Zeitstempel: 0x55507fe0
Ausnahmecode: 0x80000003
Fehleroffset: 0x00080f69
ID des fehlerhaften Prozesses: 0x12c4
Startzeit der fehlerhaften Anwendung: 0xsteamwebhelper.exe0
Pfad der fehlerhaften Anwendung: steamwebhelper.exe1
Pfad des fehlerhaften Moduls: steamwebhelper.exe2
Berichtskennung: steamwebhelper.exe3
Error: (06/05/2015 11:12:00 PM) (Source: Avira Antivirus) (EventID: 4117) (User: NT-AUTORITÄT)
Description: Die Lizenzdatei enthält keine gültige Lizenz. Der Dienst wird beendet!
Error: (06/04/2015 08:49:33 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm csgo.exe, Version 0.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 87c
Startzeit: 01d09ef1e481feb8
Endzeit: 330
Anwendungspfad: C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
Berichts-ID:
Error: (06/02/2015 11:51:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: gimp-2.8.exe, Version: 2.8.14.0, Zeitstempel: 0x00000000
Name des fehlerhaften Moduls: gimp-2.8.exe, Version: 2.8.14.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000002bbbe9
ID des fehlerhaften Prozesses: 0xf84
Startzeit der fehlerhaften Anwendung: 0xgimp-2.8.exe0
Pfad der fehlerhaften Anwendung: gimp-2.8.exe1
Pfad des fehlerhaften Moduls: gimp-2.8.exe2
Berichtskennung: gimp-2.8.exe3
Error: (05/29/2015 08:10:08 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm csgo.exe, Version 0.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 13c4
Startzeit: 01d09a0fd2d972dc
Endzeit: 787
Anwendungspfad: C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
Berichts-ID:
Error: (05/29/2015 11:19:59 AM) (Source: Google Update) (EventID: 20) (User: Dali-PC)
Description: Network Request Error.
Error: 0x80072ee7. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=auto, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=IE, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=auto, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80072ee7
Error: (05/28/2015 07:29:01 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm csgo.exe, Version 0.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 81c
Startzeit: 01d0994bcfc9ad8f
Endzeit: 919
Anwendungspfad: C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
Berichts-ID:
Error: (05/23/2015 07:40:11 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm VetoClient.exe, Version 1.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: fa0
Startzeit: 01d0957f53e45c86
Endzeit: 3
Anwendungspfad: C:\Users\Dali\Downloads\VetoClient.exe
Berichts-ID:
System errors:
=============
Error: (06/07/2015 01:54:32 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
Avgldx64
Error: (06/07/2015 01:12:00 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (06/07/2015 01:11:59 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "PnkBstrA" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/07/2015 01:11:59 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Druckwarteschlange" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (06/07/2015 01:11:58 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "AMD External Events Utility" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/07/2015 00:53:34 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
Avgldx64
Error: (06/07/2015 00:51:29 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (06/07/2015 00:51:29 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Live ID Sign-in Assistant" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (06/07/2015 00:51:29 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (06/07/2015 00:51:26 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Windows Search" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler:
%%1056
Microsoft Office:
=========================
Error: (06/07/2015 02:37:43 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Steam.exe2.81.34.655708ca6unknown0.0.0.000000000c0000005099aab3088001d0a08e9ad61ee3C:\Program Files (x86)\Steam\Steam.exeunknown683ee885-0cad-11e5-938f-20cf30d2a21e
Error: (06/06/2015 03:53:47 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: FRST64.exe6.6.2015.0bc401d0a05e75a63bfd8C:\Users\Dali\Downloads\FRST64.exe
Error: (06/06/2015 02:59:07 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: steamwebhelper.exe2.81.34.655708c89libcef.dll3.2272.30.055507fe08000000300080f6912c401d09ff3f0cb0610C:\Program Files (x86)\Steam\bin\steamwebhelper.exeC:\Program Files (x86)\Steam\bin\libcef.dll3b233898-0be7-11e5-9bf6-20cf30d2a21e
Error: (06/05/2015 11:12:00 PM) (Source: Avira Antivirus) (EventID: 4117) (User: NT-AUTORITÄT)
Description: 0x0
Error: (06/04/2015 08:49:33 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: csgo.exe0.0.0.087c01d09ef1e481feb8330C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
Error: (06/02/2015 11:51:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: gimp-2.8.exe2.8.14.000000000gimp-2.8.exe2.8.14.000000000c000000500000000002bbbe9f8401d09d7e20320569C:\Program Files\GIMP 2\bin\gimp-2.8.exeC:\Program Files\GIMP 2\bin\gimp-2.8.exe85fc3981-0971-11e5-a281-20cf30d2a21e
Error: (05/29/2015 08:10:08 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: csgo.exe0.0.0.013c401d09a0fd2d972dc787C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
Error: (05/29/2015 11:19:59 AM) (Source: Google Update) (EventID: 20) (User: Dali-PC)
Description: Network Request Error.
Error: 0x80072ee7. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=auto, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=IE, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=auto, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80072ee7
Error: (05/28/2015 07:29:01 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: csgo.exe0.0.0.081c01d0994bcfc9ad8f919C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
Error: (05/23/2015 07:40:11 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: VetoClient.exe1.0.0.0fa001d0957f53e45c863C:\Users\Dali\Downloads\VetoClient.exe
CodeIntegrity Errors:
===================================
Date: 2014-02-09 11:16:01.918
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\vrtaucbl.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-02-09 11:16:01.809
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\vrtaucbl.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-02-09 08:56:00.698
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\vrtaucbl.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-02-09 08:56:00.604
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\vrtaucbl.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-02-09 07:04:42.548
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\vrtaucbl.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-02-09 07:04:42.454
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\vrtaucbl.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-02-08 19:56:19.350
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\vrtaucbl.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-02-08 19:56:19.228
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\vrtaucbl.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-02-08 19:45:43.396
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\vrtaucbl.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-02-08 19:45:43.277
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\vrtaucbl.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i3 CPU M 370 @ 2.40GHz
Percentage of memory in use: 39%
Total physical RAM: 3948.54 MB
Available physical RAM: 2392.57 MB
Total Pagefile: 7895.28 MB
Available Pagefile: 5917.6 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:102.68 GB) (Free:27.8 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 2A2FD9A0)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=102.7 GB) - (Type=07 NTFS)
==================== End of log ============================ --- --- --- |